Security

Your funds stay on your exchange.

TIYlab places orders through limited API permissions. Security relies on several complementary controls and on the correct configuration of your account.

Funds remain under your control

Your assets stay on your own exchange. TIYlab never takes custody.

Withdrawals disabled

API keys must have no withdrawal access. Permissions are checked during onboarding.

Encrypted secrets

Stored API credentials are encrypted with AES-256-GCM and are never displayed in plain text.

IP restriction

IP whitelisting is required or strongly recommended depending on the exchange.

Continuous controls

Runtime guards, position reconciliation and alerts monitor operational inconsistencies.

Client isolation

Each API key belongs to one client and every bot state is stored separately.

Your part of security

Enable two-factor authentication on Telegram and your exchange, use a dedicated API key, review every permission and do not trade manually on the account operated by TIYlab.

No information system can fully eliminate market, exchange, availability or cybersecurity risks.